Re: Problems with SPF, solutions, and a timeline.
John Levine <[email protected]> 28 Feb 2004 15:01:45 -0000
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Organization | I.E.C.C., Trumansburg NY USA |
| Message-ID | <[email protected]> |
>| I would argue that the biggest weakness of all the LMAP systems is >| that the domain they test, the one in the envelope bounce address, ... >That's fine by me as long as I stop getting the bounce messages. I'd like to stop getting bounce messages, too, but it sounds like you're agreeing that LMAP schemes will not in fact deter any spam since spammers can easily evade it by using either their own throwaway domains or any of the millions of domains that will never publish LMAP records. If so, why bother? We should move directly to a signature scheme like domain keys in which each protected message makes a directly verifiable assertion that it's good, rather than an LMAP scheme where the message says nothing and you have to intuit the domain owner's intentions indirectly. >| Another issue is one-way mail domains like Meng's pobox.com. ... >Actually, for the past three years we've offered SMTP AUTH on 587 to all >our users, and now we're going to try to start chivvying them towards it. > >Of course, they are perfectly free to ignore that; if they want to set >up per-user SPF records, they are welcome to set that up too. Pobox is fairly unusual in that its users pay for the mailboxes so it has a budget. All the other one-way forwarders I can think of, including many that are very widely used such as acm.org, ieee.org, and cornell.edu (once you have a Cornell address, it's yours forever) are provided to members of an organization as a low-cost benefit. Per-user SPF records don't strike me as very practical, since the implementation and scaling problems are substantial for any domain with an interesting number of users. If you're going to publish per-user data, you might as well publish per-user S/MIME keys (or a signing key for all the users' keys) and be done with it. Maybe it'll turn out that in fact one-way forwarders are too risky, and we'll all have to demand that they become two-way or die, but that's another cost that has to be made explicit if we're serious. -- John R. Levine, IECC, POB 727, Trumansburg NY 14886 +1 607 330 5711 [email protected], Village Trustee and Sewer Commissioner, http://iecc.com/johnl, Member, Provisional board, Coalition Against Unsolicited Commercial E-mail